4.6.3 Ensure that IPsec filters are active

Information

Rules added to the filter list are not enabled automatically. Filters need to be activated and/or updated after changes to the ODM filter database.

The filters must be active in order for IP Security to protect the system.

Solution

mkfilt -u
mkfilt -g start

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

Ensure you have access to the console (e.g., via HMC) while developing and testing IPsec rule modifications.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 5735fee981a9476beb4c423795a27d3f96ef8e8132fbdc17c81e1d576d2fee0d